WinSecWiki
Windows Security Settings
Articles
WinSecWiki
»
Windows Security Settings
»
Local Policies
»
Audit Policy
»
Audit policy change
»
Authorization Policy Change
Authorization Policy Change
Authorization Policy Change
I've only isolated a few events logged by this category. Let me know via a discussion post on this event if you know of more. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.
Coverage on events generated by this category are currently in the
Security Log Encyclopedia
:
Event ID
Title
4704
A user right was assigned.
4705
A user right was removed.
4714
Encrypted data recovery policy was changed.
Add Your Comments
Name:
*
Email Address:
Web Address:
Verification Code:
*
Details
Applies To:
Vista, Windows Server 2008, Windows Server 2008 R2, Windows 7, Windows 8, Windows Server 2012
Rated 2 stars based on 1 vote.
Article has been viewed 2,190 times.
Options
Bookmark Article
Social Bookmarks
Comments RSS
Upcoming Webinars
3 Ways Two-Factor Authentication Can Stop APTs from Spreading
Understanding the Security Boundaries and Risks of Multiple Domains, Forests and Trust Relationships
6 Steps to Classifying Your Data
Top 6 Security Events to Monitor in SQL Server
Top 10 Security Events to Monitor in SharePoint
Additional Resources
Security Log Quick Reference Chart
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
User name:
Password:
/
Forgot?
Register
Home